CVE-2023-34967: Debian Linux
Medium severity, CVSS 5.3. EPSS: 61.2% chance of exploitation in the next 30 days.
A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the mdssvc protocol. Due to a lack of type checking in callers of the dalloc_value_for_key() function, which returns the object associated with a key, a caller may trigger a crash in talloc_get_size() when talloc detects that the passed-in pointer is not a valid talloc pointer. With an RPC worker process shared among multiple client connections, a malicious client or attacker can trigger a process crash in a shared RPC mdssvc worker process, affecting all other clients this worker serves.
Affected products
- Debian Debian Linux: version 11.0 only; version 12.0 only
- Fedoraproject Fedora: version 37 only; version 38 only
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
- Samba Samba: before 4.16.11 (fixed in 4.16.11); from 4.17.0, before 4.17.10 (fixed in 4.17.10); from 4.18.0, before 4.18.5 (fixed in 4.18.5)
Published 2023-07-20. Last modified 2026-06-17.